One thing most Second Life users like to do is share images. The regular way costs 10 Lindens per picture, the fee to upload a picture. So many turn to links of images they put on places on the Internet, such as Facebook or Discord. But those who don't have the software of such places won't see them. So many of them turn to Gyazo, an image sharing platform one doesn't need the software to see the links. Over time, it's become popular, with over 23 million users.
But earlier this month, they were hacked. On Wednesday September 16, Helpfeel, the company behind Gyazo, issued the following:
Gyazo, our image-sharing service, was subject to unauthorized access by a third party, resulting in the unauthorized disclosure of user information and certain metadata associated with uploaded images.
We have blocked all access routes used in the incident and have completed remediation of the vulnerability that was exploited. We continue to prioritize measures to prevent further harm while investigating the scope and impact of the incident.
Gyazo, our image-sharing service, was subject to unauthorized access by a third party, resulting in the unauthorized disclosure of user information and certain metadata associated with uploaded images.
We have blocked all access routes used in the incident and have completed remediation of the vulnerability that was exploited. We continue to prioritize measures to prevent further harm while investigating the scope and impact of the incident.
They would go on to say on Friday Sept 11, "a third party exploited a vulnerability in Gyazo’s image upload server to gain unauthorized access to our systems and execute arbitrary commands." They soon sensed something was wrong, and by the next morning had blocked the hacker. But the damage was done, "We have confirmed that approximately 23.62 million records containing data related to Gyazo users were disclosed without authorization." The information included user emails, passwords, user and device IDs, and more. Thankfully "no payment information, including credit card numbers, was disclosed."
The company planned to email all users whose information was compromised, "To help prevent further harm resulting from this incident, we ask all Gyazo users to change their passwords. If you use the same or a similar password for Gyazo and any other services, we ask that you also change your passwords for those services."
Also, "the hackers also obtained a list identifying private images, and the company cannot rule out that some were viewed." Service was suspended to all affected accounts.
"We sincerely apologize to all Gyazo users and other affected parties for the significant concern and prolonged inconvenience caused by this incident."
Sources: Helpfeel, Bleepingcomputer.com .
Bixyl Shuftan


No comments:
Post a Comment